Offensive security, run like an engineering firm.
We break into systems with permission, explain exactly how, and stay until the fix is verified.
Authorized, in writing, every time.
No engagement starts without signed rules of engagement. We only test systems you own or control, and we stop the moment you ask.
Humans, not scanners.
Automation finds the known. Our consultants find the chains, the logic flaws, and the misconfigurations that turn a low finding into a breach.
Findings you can act on.
Every finding ships with reproduction steps, evidence, and a fix. If your engineers cannot reproduce it, we have not finished.
Retest included.
Verifying that fixes work is part of the job, not an upsell. The closure letter is what you hand to auditors and customers.
The people who do the work.
Every engagement is led by a named consultant who is on the call at scoping, during testing, and at the walkthrough.
Leila Haddad
Founder and Lead Consultant
OSCP, CREST CRT
Twelve years in offensive security, previously leading application testing for a European payments network.
Daniel Okonkwo
Head of Red Team
OSCE3, CRTO
Runs adversary simulations for financial services and critical infrastructure clients.
Sofia Marchetti
Cloud Security Lead
CCSP, AWS Security Specialty
Former platform engineer who reviews cloud estates the way she used to build them.
Rhys Llewellyn
Incident Response Lead
GCFA, GCIH
Has led response for ransomware, insider, and supply-chain incidents across the UK and EU.
Accreditation and how we hold ourselves to it.
- CREST member company
- Cyber Essentials Plus certified
- ISO 27001 aligned information security program
- Consultants hold OSCP, OSCE3, CCSP, GCFA, and CISSP
We expect to be tested too. If you find a security issue in one of our systems, our responsible disclosure policy explains how to report it and what you can expect from us.
Talk to the consultant, not a sales team.
Scoping calls are run by the person who will lead your engagement. Bring the system, the deadline, and the hard questions.